CVE-2021-23758

HIGH8.1Publiée le 3 décembre 2021

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Alerte précoce : exploitation observée

  • Exploitation observée depuis le 20 août 2026
  • Pas encore dans le catalogue officiel de la CISA
  • Première attaque observée 1720 jours après la divulgation

Source : VulnCheck KEV · 20 août 2026

Score CVSS8.1 / 10CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Type de faiblesse (CWE)CWE-502
Éditeursajaxpro.2 project

Produits concernés

ÉditeursProdottoVersioni
ajaxpro.2 projectajaxpro.2< 21.10.30.1

Articles liés

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de données CVE